TL;DR: Agentic AI is lowering the cost of fraud while accelerating attacker throughput, according to Arkose Labs, with Deloitte’s Center for Financial Services projecting US AI-facilitated fraud losses will reach $40 billion by 2027, up from $12.3 billion in 2023. The real shift is that fraud controls must now make attacking economically irrational before scale overwhelms detection.
Editorial analysis by NHI Mgmt Group, based on content published by Arkose Labs: “The Economics of Fraud Have Changed. Here’s Why.”.
By the numbers:
- AI-facilitated fraud losses in the US will reach $40 billion by 2027, up from $12.3 billion in 2023, according to Deloitte’s Center for Financial Services cited by Arkose Labs.
- Arkose Labs says FraudGPT is available for $1,700 per year.
- Arkose Labs says Gartner predicts that by 2028, 25% of enterprise breaches will trace back to AI agent abuse.
Key questions
Q: What breaks when fraud controls treat all automation the same?
A: When fraud controls treat all automation the same, they either block legitimate AI assistants and accessibility tools or allow malicious agentic traffic through.
Q: Why do agentic AI attacks change the cost of fraud?
A: Agentic AI lowers the attacker’s cost of experimentation, scaling, and adaptation, which makes many fraud schemes economically viable at lower skill levels.
Q: How do you know if fraud deterrence is actually working?
A: Deterrence is working when attackers abandon the target, not just when individual attempts fail.
Practitioner guidance
- Define a three-tier traffic classification model Separate self-disclosing good agents, non-disclosing good agents, and malicious agents so policy can distinguish legitimate automation from abuse at runtime.
- Measure attacker economics, not only detection rates Track the time, compute, retry cost, and operational friction that your controls impose on fraud attempts, then tune for higher attacker spend per successful session.
- Replace binary bot rules with behavioural intent signals Use session-level behaviour, interaction patterns, and context across the flow to decide whether automation is authorised, ambiguous, or hostile.
Bottom line: Agentic AI has shifted fraud prevention from a simple detection challenge to an economic contest over attacker cost and defender friction.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI turns fraud prevention into an economics problem, not just a detection problem. When the cost of launching abuse falls faster than the cost of defending against it, the security model breaks at the incentive layer. Static blocking can still stop individual attempts, but it does not change the attacker’s business case. Practitioners should treat attacker ROI as a control objective, not a side effect.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: What should organisations measure if they want to know fraud controls are working?
A: Organisations should measure whether controls are increasing attacker cost, reducing campaign success rates, and forcing repeated abuse to become uneconomic. A control can reduce one attempt and still fail strategically if attackers can immediately retry at low cost. The right metric is not only detection, but deterrence.
👉 Read our full editorial: Agentic AI is changing the economics of fraud prevention
Agentic AI turns fraud prevention into an economics problem, not just a detection problem. When the cost of launching abuse falls faster than the cost of defending against it, the security model breaks at the incentive layer. Static blocking can still stop individual attempts, but it does not change the attacker’s business case. Practitioners should treat attacker ROI as a control objective, not a side effect.
A few things that frame the scale:
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: What should organisations measure if they want to know fraud controls are working?
A: Organisations should measure whether controls are increasing attacker cost, reducing campaign success rates, and forcing repeated abuse to become uneconomic. A control can reduce one attempt and still fail strategically if attackers can immediately retry at low cost. The right metric is not only detection, but deterrence.
👉 Read our full editorial: Agentic AI is changing the economics of fraud prevention
Agentic AI turns fraud prevention into an economics problem, not a detection problem. The article is right to frame the shift this way because attacker cost, reuse speed, and adaptation now define fraud volume more than raw sophistication. Detection still has value, but it no longer sets the boundary condition for success. Practitioners should treat control design as a pricing problem for abuse, not just a visibility problem.
A few things that frame the scale:
- U.S. fraud losses are projected to reach $40 billion by 2027.
A question worth separating out:
Q: What should security teams do when legitimate AI agents share signals with malicious bots?
A: Security teams should classify traffic by intent and behaviour, then apply graduated friction instead of a blanket block. That approach preserves authorised automation while forcing hostile sessions to pay a higher operational cost, which is the point of economic deterrence.
👉 Read our full editorial: Agentic AI is changing the economics of fraud prevention